Tag: Cryptocurrency ransom

  • Spanish Police Arrest 16-Year-Old Accused of Running KillSec Ransomware Group

    Spanish Police Arrest 16-Year-Old Accused of Running KillSec Ransomware Group

    Key Highlights:

    • Operation KillSwitch targeted the Kill Security Ransomware Group, known as KillSec, in a coordinated U.S.-European investigation.
    • Authorities searched eight properties across Spain, Greece, Romania and the UK and seized control of five central servers.
    • Fouad Eltibrizi, a Dutch national living in the UK, faces U.S. extradition proceedings over alleged cyberattacks conducted under the handle Archduke.

    Operation KillSwitch targets KillSec ransomware network

    The September 30 operation was part of Operation KillSwitch, an investigation led by the Hamburg State Criminal Police Office and the Hamburg public prosecutor’s office into approximately 1,000 suspected cyberattacks worldwide. Investigators have so far identified about 500 attacks as successful.

    Authorities searched eight properties in Spain, Greece, Romania and the UK as part of the coordinated action. The operation targeted Kill Security Ransomware Group, commonly known as KillSec, and resulted in police taking control of five central servers. Several domains were also redirected to a seizure notice while investigators examine confiscated devices and trace the group’s proceeds, including cryptocurrency.

    Today we’re announcing Operation KillSwitch, a joint sequenced operation led by @FBISanJuan targeting the Kill Security Ransomware Group (“KillSec”). Authorities in the U.S. and Europe took control of KillSec’s leak site, securing at least 110 terabytes of data against further… pic.twitter.com/ZYvxosEPyv

    — FBI Cyber Division (@FBICyberDiv), October 1, 2026

    Fouad Eltibrizi faces extradition over alleged cyberattacks

    The man arrested in Britain faces charges in the United States. Fouad Eltibrizi, a Dutch national resident in the UK who allegedly used the online handle Archduke, was indicted by a federal grand jury in Puerto Rico on September 16.

    The indictment charges Eltibrizi with conspiracy to access computers without authorization for financial gain, damaging protected computers and transmitting extortion threats. He was arrested within the following two weeks and faces extradition proceedings. The charges carry a maximum penalty of 10 years.

    KillSec breaches and cryptocurrency ransom demands

    U.S. prosecutors allege that KillSec published details of a Puerto Rico breach on its leak site in March 2025, including samples of stolen patient data and a seven-day countdown. After the organization failed to respond, approximately 180GB of data was released. The indictment also describes comparable breaches in California, Washington State and Louisiana.

    Europol said KillSec had been active since around 2024, exploiting software vulnerabilities and poorly secured access points—particularly those connected to cloud storage—to enter organizations’ systems. The group allegedly copied internal data to infrastructure it controlled, named victims on its dark web leak site and threatened to publish the stolen information unless a ransom was paid. When victims did not pay, files were made available for free download.

    The group used a double-extortion model: encrypting victims’ servers and threatening to publish stolen data even when organizations refused to pay because they had backups. Switzerland’s federal police said ransoms were frequently demanded in cryptocurrency. Swiss prosecutors have investigated attacks on Swiss companies since July 2025, covering incidents reported between October 2023 and June 2025.

    Investigators also found that KillSec had used artificial intelligence to build and maintain its ransomware infrastructure and to identify potential victims. Europol’s European Cybercrime Centre supported the investigation with cryptocurrency tracing and digital-forensics expertise as authorities worked to follow the group’s financial activity.

    UK police identify 28 victim companies

    In the UK, authorities have identified 28 victim companies. Officers from the Eastern Region Special Operations Unit arrested a 25-year-old suspect at an address in Levenshulme, Manchester. Police allege that the suspect negotiated with victims.

    “Ransomware causes “significant financial losses, operational disruption and harm to public confidence,” Detective Sergeant John Collinson of the unit’s cyber crime team said.

    Why This Matters

    Operation KillSwitch demonstrates the international scope of the investigation into KillSec and the growing importance of cross-border cooperation in ransomware cases. The seizure of servers, redirection of leak-site domains and ongoing cryptocurrency tracing could help investigators connect cyberattacks to the infrastructure and proceeds used by the group.

    The case also highlights the risks posed by cloud-security weaknesses, double-extortion tactics and the use of AI in ransomware operations. Authorities are continuing to examine seized devices and identify the full impact of the suspected attacks.

    Frequently Asked Questions

    What is Operation KillSwitch?

    Operation KillSwitch is a coordinated investigation led by the Hamburg State Criminal Police Office and the city’s public prosecutor, with U.S. and European authorities targeting the Kill Security Ransomware Group, or KillSec.

    Who is Fouad Eltibrizi?

    Fouad Eltibrizi is a Dutch national living in the UK who allegedly used the handle Archduke. He was indicted in Puerto Rico and arrested in Britain over charges linked to unauthorized computer access, damage to protected computers and extortion threats.

    How did KillSec allegedly operate?

    KillSec allegedly exploited software vulnerabilities and insecure access points, copied internal data, encrypted servers and threatened to publish stolen information unless victims paid cryptocurrency ransoms.